Samsung's Flagship Falls Again on Day Two
Pwn2Own Ireland 2026, running October 6–9 in Cork, Ireland, continued its second day with researchers collecting $232,500 for 45 unique zero-day vulnerabilities. The marquee target once again was Samsung's flagship Galaxy S26, which was successfully exploited three more times — on top of the three successful attempts already recorded against it on day one.
Day Two Details
| Attribute | Value |
|---|---|
| Event | Pwn2Own Ireland 2026 |
| Organizer | Zero Day Initiative (ZDI / Trend Micro) |
| Location | Cork, Ireland |
| Dates | October 6–9, 2026 |
| Day two payout | $232,500 |
| Day two zero-days exploited | 45 |
| Running Galaxy S26 compromise count | 6 (3 on day one, 3 on day two) |
Galaxy S26 Compromised By Three More Teams
Three separate research teams each successfully exploited the Samsung Galaxy S26 on day two:
- KAIST Hacking Lab (Kyeongmin Kim)
- PetoWorks
- Mobile Hacking Lab (Dimitrios Valsamaras and Ken Gannon)
That brings the device's total compromise count to six across the contest's first two days, following day-one exploits from Interrupt Labs, Ikotas Labs, and Viettel Cyber Security's Nguyen Thanh Dat. Samsung's unreleased flagship is now facing remediation work across at least six independent exploit chains before the standard 90-day disclosure window closes.
Kyeongmin Kim also attempted a USB-based attack against the Google Pixel 10 during day two, but withdrew the attempt before it concluded — one of the contest's few notable non-completions on the day.
Smart Home, AI Infrastructure, and Speakers Also Hit
Day two's other successful exploits spanned several of the contest's newer target categories:
- Sonos Era 300: Jack Dates of RET2 Systems demonstrated a full exploit chain against the smart speaker in under 60 seconds
- Dynamo (AI infrastructure): HaeJung Yang of the Out of Bounds team earned $40,000 for a successful chain
- Home Assistant Green: Compromised by multiple researchers, including members of PetoWorks and Doyensec
- Oracle Autonomous AI Database: Ikotas Labs chained seven zero-day bugs to compromise the database, a day after the same target fell to a different five-bug chain from VinSOC
Why This Matters
The repeated, independent compromise of the Galaxy S26 — six separate successful chains across just two days, by six different teams — signals systemic weaknesses in the device's security posture rather than a single isolated bug. Samsung now has a 90-day coordinated-disclosure clock running against all six chains simultaneously, a significant remediation lift for a device that has not yet reached general retail availability.
The continued focus on AI infrastructure (Oracle's Autonomous AI Database, falling to two different exploit chains across two days) reinforces a trend already visible from day one: AI-adjacent infrastructure is now a first-class target at Pwn2Own, not a novelty category, and vendors shipping AI database or AI-agent tooling should expect the same adversarial scrutiny long applied to browsers and mobile OSes.
Recommended Actions
For IT Administrators
- Treat Samsung, Oracle (Autonomous AI Database), Sonos, and Home Assistant as priority watch items for emergency patches over the coming weeks
- Inventory any Galaxy S26 devices already in BYOD or pre-release testing programs so patches can be pushed immediately once Samsung ships fixes
For Security Teams
- Subscribe to ZDI's advisory feed to track the 90-day disclosure windows opened by day two's 45 bugs, layered on top of day one's 32
- If running Oracle Autonomous AI Database or similar AI infrastructure, review deployment hardening now rather than waiting for the technical write-ups to drop in 90 days
For End Users
- Install Samsung, Sonos, and Home Assistant firmware/app updates promptly once released
- Keep smart speakers and home-automation hubs off direct internet exposure and on segmented home networks
Key Takeaways
- Day two of Pwn2Own Ireland 2026 produced 45 zero-days and $232,500 in payouts.
- The Samsung Galaxy S26 was hacked three more times — by KAIST Hacking Lab, PetoWorks, and Mobile Hacking Lab — bringing its two-day total to six successful compromises.
- Oracle's Autonomous AI Database was exploited again, this time via a seven-bug chain from Ikotas Labs, following a separate five-bug chain the day before.
- Jack Dates of RET2 Systems compromised a Sonos Era 300 in under 60 seconds.
- The contest continues through October 9, with further attempts expected against remaining targets.